Digital Wallet

Story: Trezor Users Targeted by Phishing Attack Using Legitimate Email Infrastructure

By Maheen Hernandez

1 / 15

How the Attack Actually Worked. The phishing emails were sent using infrastructure that was authorized to send messages on…

2 / 15

Brevo, BitBox, and a Possible Wider Breach. Community investigators pointed fingers at Brevo, an email marketing provider, as the likely…

3 / 15

What Trezor Is Doing Now. The company is investigating how attackers gained access to the authorized email infrastructure…

4 / 15

Trezor got hit. Hard. A sophisticated phishing campaign reached hardware wallet users after attackers broke into the company's third-party email provider, sending fraudulent…

5 / 15

The emails weren't just convincing — they were technically authenticated. They passed SPF, DKIM, and DMARC checks, which basically means Gmail displayed them as "signed-by: trezor.

6 / 15

Trezor took down the affected domain fast.

7 / 15

The phishing emails were sent using infrastructure that was authorized to send messages on Trezor's behalf. That's the key detail here.

8 / 15

The message itself pushed urgency hard. It claimed Trezor devices had a critical entropy vulnerability — a scary-sounding technical flaw — and pushed users to complete a fake…

9 / 15

One detail that surfaced through community investigators: the phishing scheme included an "offline" HTML file.

10 / 15

Trezor hasn't said how many customers received the phishing message. No number. No estimate. Unclear when or if they'll disclose that.

11 / 15

Community investigators pointed fingers at Brevo, an email marketing provider, as the likely source of the breach. Trezor hasn't confirmed that.

12 / 15

See also: Ledger CTO Calls Out “Attention Farming” as AI Risks Exposing Wallet Vulnerabilities

13 / 15

But here's what makes this messier: users of BitBox and CoinTracking also reported getting suspicious emails around the same time. That overlap is hard to ignore.

14 / 15

That's not confirmed. But it's probably the most logical explanation floating around right now.

15 / 15

Trezor also dealt with a separate incident back in August, involving ShipMonk, a shipping provider. That breach exposed customer data.

The Currency Analytics

Want the full story?